@tokens-studio/tokenscript-interpreter
A TypeScript interpreter for TokenScript, a domain-specific language for design token manipulation and computation
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/lib/chunk-7VYDV5HH.js | AI (source-diff): Bundled interpreter source code, not a dropper; false positive on minified build output. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-2EWAFMZK.cjs | AI (source-diff): Bundled interpreter source code, not a dropper; false positive on minified build output. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-IPRRPG6G.js | AI (source-diff): Bundled tsup output of interpreter source; no actual network+exec payload in sample. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-RMSLWL7U.cjs | AI (source-diff): Bundled tsup output of interpreter source; no actual network+exec payload in sample. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-Y6RHSTUS.js | AI (source-diff): Bundled tsup output containing interpreter source, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-D7VLJTD4.cjs | AI (source-diff): Bundled tsup output containing interpreter source, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-IQQQZZRV.js | AI (source-diff): Bundled interpreter source, not a dropper; tsup chunk output. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-RQ6HB2ZY.cjs | AI (source-diff): Bundled interpreter source, not a dropper; tsup chunk output. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-FCQEBUOM.js | AI (source-diff): Bundled interpreter source (tsup output), not a dropper; pattern-match false positive. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-3MJQJ4NH.cjs | AI (source-diff): Bundled interpreter source (tsup output), not a dropper; pattern-match false positive. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-X4ZXEY3T.js | AI (source-diff): Bundled interpreter code, same pattern as sibling chunk; false positive. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-HPWRRVKH.cjs | AI (source-diff): Bundled interpreter code (AST/eval for the DSL), not dropper behavior; verified via sample. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-G5U5VB7A.js | AI (source-diff): tsup bundle chunk of interpreter source, not a dropper; no real net+exec behavior shown. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-OD763557.cjs | AI (source-diff): tsup bundle chunk of interpreter source, not a dropper; no real net+exec behavior shown. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-P2ZDF54L.js | AI (source-diff): Bundled interpreter source, not a dropper; matches package's stated interpreter functionality. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-KEWDBGFQ.cjs | AI (source-diff): Bundled interpreter source, not a dropper; matches package's stated interpreter functionality. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-SI7WCMJ2.cjs | AI (source-diff): Bundled tsup output for interpreter parser code; no actual network/exec malware behavior in sample. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-5KYRGKVP.js | AI (source-diff): Bundled tsup output for interpreter parser code; no actual network/exec malware behavior in sample. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-5AA6YMY4.js | AI (source-diff): Bundled tsup output of interpreter source, not a dropper; no real net+exec payload. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-N4BGH3OA.cjs | AI (source-diff): Bundled tsup output of interpreter source, not a dropper; no real net+exec payload. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-W7NANE66.js | AI (source-diff): Bundled tsup output containing normal interpreter code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-C5FK5V3K.cjs | AI (source-diff): Bundled tsup output containing normal interpreter code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-QE3EI3W6.js | AI (source-diff): Bundled build output from tsup, not a dropper; sample shows plain interpreter source. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-WN764DNR.cjs | AI (source-diff): Bundled build output from tsup, not a dropper; sample shows plain interpreter source. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-L4BPLNTU.js | AI (source-diff): Bundled interpreter source (tsup output), false positive on generic keywords. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-VIOAQBJM.cjs | AI (source-diff): Bundled interpreter source, not a loader; no real exfil/exec behavior in sample. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-IU4UODCJ.js | AI (source-diff): Bundled interpreter source (tsup output), no malicious network/exec behavior present. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-HXJAUUE2.cjs | AI (source-diff): Bundled interpreter source (tsup output), no malicious network/exec behavior present. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-TU5CEMMK.cjs | AI (source-diff): Bundled interpreter code, no actual dropper/loader behavior in sample. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-HFYT7IMO.js | AI (source-diff): Bundled interpreter code, no actual dropper/loader behavior in sample. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-X632L3QL.js | AI (source-diff): Sample is bundled interpreter AST code, no actual network+exec behavior. | ai | |
| source-diff | net-exec-file:dist/lib/chunk-EUXOEBNN.cjs | AI (source-diff): Sample is bundled interpreter AST code, no actual network+exec behavior. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Internal team rotation within Tokens Studio org; new maintainer shares org namespace. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large files are source maps and compiled bundles consistent with major version bump. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is first-party @tokens-studio/schema-validation replacing zod; low risk. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal paired with same-org addition; consistent with team handoff, not takeover. | ai | |
| provenance | no-provenance | AI (provenance): No provenance is common; no other risk signals present to elevate this. | ai |
Versions (showing 51 of 56)
| Version | Deps | Published |
|---|---|---|
| 0.38.0 | 4 / 11 | |
| 0.37.1 | 4 / 11 | |
| 0.37.0 | 4 / 11 | |
| 0.36.4 | 4 / 11 | |
| 0.36.3 | 4 / 11 | |
| 0.36.2 | 4 / 11 | |
| 0.36.1 | 4 / 11 | |
| 0.36.0 | 4 / 11 | |
| 0.34.0 | 4 / 11 | |
| 0.33.0 | 4 / 11 | |
| 0.32.0 | 4 / 11 | |
| 0.31.0 | 4 / 11 | |
| 0.30.0 | 4 / 11 | |
| 0.29.1 | 4 / 11 | |
| 0.29.0 | 4 / 11 | |
| 0.28.0 | 4 / 11 | |
| 0.27.0 | 4 / 11 | |
| 0.26.0 | 4 / 11 | |
| 0.25.0 | 4 / 11 | |
| 0.24.0 | 4 / 11 | |
| 0.23.1 | 4 / 11 | |
| 0.23.0 | 4 / 11 | |
| 0.22.0 | 4 / 11 | |
| 0.21.0 | 4 / 11 | |
| 0.20.0 | 4 / 11 | |
| 0.19.0 | 4 / 11 | |
| 0.18.1 | 4 / 11 | |
| 0.18.0 | 4 / 11 | |
| 0.17.2 | 4 / 11 | |
| 0.17.1 | 4 / 11 | |
| 0.17.0 | 4 / 11 | |
| 0.16.1 | 4 / 11 | |
| 0.16.0 | 4 / 11 | |
| 0.15.1 | 4 / 11 | |
| 0.15.0 | 4 / 11 | |
| 0.14.0 | 4 / 11 | |
| 0.13.3 | 4 / 11 | |
| 0.13.2 | 4 / 11 | |
| 0.13.1 | 4 / 11 | |
| 0.13.0 | 4 / 11 | |
| 0.12.1 | 4 / 11 | |
| 0.12.0 | 4 / 11 | |
| 0.11.3 | 4 / 11 | |
| 0.11.1 | 4 / 11 | |
| 0.11.0 | 4 / 11 | |
| 0.10.0 | 4 / 11 | |
| 0.9.0 | 4 / 11 | |
| 0.8.4 | 4 / 11 | |
| 0.8.3 | 4 / 11 | |
| 0.8.2 | 4 / 11 | |
| 0.8.0 | 4 / 11 |
v0.31.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.21.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.20.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.19.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.